How we think about security and evidentiary integrity
ZoneLex is being built to meet the evidentiary standards land-use legal teams are held to. This page describes our approach and where our SOC 2 program stands today.
Chain of custody
Land use work turns on the record. A finding is only as good as the document behind it, and a document is only as good as the ability to show where it came from.
ZoneLex is being built so that every fact it surfaces carries its provenance with it: the source record, the issuing jurisdiction or agency, the date it was retrieved, and a link back to the original. Nothing is presented as an unattributed conclusion. When a record is superseded, the prior version stays available rather than being silently replaced, so a timeline can be reconstructed as it existed on any given date.
Data handling
We distinguish between two kinds of data in the ZoneLex platform, and we treat them differently.
Public records — codes, ordinances, permits, parcel data, hearing records and similar material published by government bodies. We ingest these from their official sources, retain them, and make them searchable.
Client data — the matter files, notes, and other material your team brings into a workspace. This belongs to you. It is encrypted in transit, processed in an isolated workspace, and segregated from other customers’ data. It is retained for as long as your agreement with us provides and deleted on request or at the end of the engagement, subject to any legal hold you tell us about.
Client data is never used to train our models, and it is never used to improve the product for anyone else. That is a contractual commitment in our customer agreements, not just a statement of intent, and it applies to any third-party model provider we work with.
This page describes the ZoneLex platform, which is a separate product governed by its own agreement. This website is much simpler: the forms here ask for contact details and a short message, and nothing you send through them should include client or matter information. See our Privacy Policy for what the website collects.
Access and controls
Access to customer workspaces is authenticated, role-based, and limited to what a person needs to do their job. Multi-factor authentication is required on accounts with access to production systems.
ZoneLex personnel do not access customer workspace content as a matter of course. Where access is needed — to resolve a support issue you have raised, or to address a security or integrity problem — it is limited, logged, and attributable to a named individual. Administrative and access events are recorded in an audit log so that activity can be reviewed after the fact.
Certifications and review
We are pursuing a SOC 2 Type II report and that program is underway now. We are working through readiness with an independent firm, documenting our controls across security, availability, and confidentiality, and building toward an observation period and formal audit.
To be precise about where that stands: ZoneLex does not yet hold a SOC 2 report. We will not describe ourselves as SOC 2 attested, certified, or compliant until an independent auditor has issued a report, and when that happens we will say so here with the report type and period. We would rather tell you exactly where we are than let a logo imply something that has not happened yet.
If your firm has a vendor security review process, we are happy to complete your questionnaires, walk your team through our architecture, and tell you plainly which controls are in place today and which are still on the roadmap.
Where we are today
ZoneLex is pre-beta. Our security program is being built alongside the product rather than bolted on after it, which is the right order but also means some of what is described here is newer than we would like it to be. We will keep this page current as controls are implemented and as our SOC 2 program progresses.
Questions, or want to see our documentation? Email contact@zonelex.com or get in touch.